Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators 73 Open VSX Sleeper Extensions Linked to Malware Show New Activations

4ebfe8f66ca7e9751060b3301b5e8838d6017593cdae748541de83bfa28183bd

TLP:CLEAR
Active

sha256

Description

The GlassWorm campaign targeting Open VSX has escalated with 73 newly identified impersonation extensions. These sleeper extensions were initially published without malicious payloads by newly created GitHub accounts, appearing benign to build trust and credibility. At least six extensions have been activated to deliver malware through normal update mechanisms. The extensions clone popular legitimate listings with similar branding, icons, and descriptions, making detection difficult. The threat actor has shifted delivery methods away from embedded loaders toward transitive delivery via extension dependencies, external payload retrieval from GitHub-hosted VSIX files, and native binary execution. Some variants use obfuscated JavaScript to decode and retrieve payloads at runtime. The malicious code targets multiple IDEs including VS Code, Cursor, Windsurf, and VSCodium, installing downloaded extensions through command-line interfaces.

Sightings (0)

No sightings recorded yet

Details

Name / Label
73 Open VSX Sleeper Extensions Linked to Malware Show New Activations
Pattern Type
STIX
Confidence
75%
Valid From
May 3, 2026 00:55
Total Sightings
0
Added
May 3, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 4ebfe8f66ca7e9751060b3301b5e8838d6017593cdae748541de83bfa28183bd

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.